Die Entwickler von Arch Linux haben die Konsequenzen aus den Angriffen der letzten Tage auf das AUR gezogen und das Repository für neue Anmeldungen vorübergehend gesperrt.
Die Entwickler von Arch Linux haben die Konsequenzen aus den Angriffen der letzten Tage auf das AUR gezogen und das Repository für neue Anmeldungen vorübergehend gesperrt.
Das Arch User Repository (AUR) sah sich am Wochenende weiteren Angriffen ausgesetzt. Eine zweite Welle manipulierter Paketbeschreibungen hält die Entwickler auf Trab.
Researchers at Sonatype uncovered a massive supply chain attack against the Arch User Repository (AUR) to harvest credentials and exfiltrate user data by hijacking around 1,500 packages.
Wieder einmal war das Arch Linux Community-Paketarchiv AUR Ziel eines Angriffs, bei den über 400 Pakete mit einer Dependency Credential Stealer Malware infiziert wurden.
It's in the AUR
In most package managers a dependency’s install-time code runs by default the moment you install it: an npm postinstall, a Setuptools setup.py, a CPAN Makefile.PL, an RPM scriptlet, a Conda post-link, a Debian postinst. A handful require explicit per-package opt-in before any of that code runs, usually called an allowlist or a trusted-dependencies list depending on the tool.
Per-package…
Hello, Mullvad browser is available on AUR.
If Arch add it on extra, we might add it.
Romanians are not rejecting Europe. They are rejecting a politics that hides behind Europe—one in which outcomes are perceived as shaped in Brussels rather than decided at home.
I don't really have time to look into it myself atm, but I would be very curious to know if the last gimp-2 (eg. from the AUR) can be compiled against this.
So it happened like always i woke up one day and decided that life isn’t really fun I SHOULD DO SOMETHING DIFFERENT and as I had lot of free time(the most important requirement for installing Linux is basically being unemployed jk) I decided making the most chad Linux setup that ever exist and it would be Artix with ZFS1 you may ask why? That’s what we would find in next…
Installed mine from AUR and it's working...I didn't know that driver is still maintained in Artix repo. Is it gonna stay in repos for a long time or just transition period?
Installed mine from AUR and it's working...I didn't know that driver is still maintained in Artix repo. Is it gonna stay in repos for a long time or just transition period?